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DETAILED ACTION 

1 . This action is in response to tine communication filed on September 30, 2005. 
Claims 1-22 were originally received for consideration. No preliminary amendments 

regarding the claims was received. 

2. Claims 1-22 are currently pending consideration. 

Information Disclosure Statement 

3. A dated and initialed copy of Applicant's IDS form 1449, received on 9/30/2005, 
is attached to this Office action. 

Claim Rejections - 35 USC § 102 

The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that 
form the basis for the rejections under this section made in this Office action: 

A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a foreign country or in public 
use or on sale in this country, more than one year prior to the date of application for patent in the United 
States. 

Claims 1-8, 11-14, 17, 21, and 22 are rejected under 35 U.S.C. 102(b) as being 
anticipated by Ensor et al. (U.S. Patent 5,721,780). 

Regarding claim 1, Ensor discloses: 

A method for providing security to a computer network by monitoring the physical 
location of a network login or login attempts said method comprising: 
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associating a workstation to a physical location (column 3, lines 1-17: identifiable 
coupling); 

associating a network user to said workstation (column 3, lines 1-17, 62-67); 
monitoring a computer network to determine a network login or attempted login of 

said user (column 4, lines 51-59); 

determining a physical location of said login or attempted login (column 4, lines 
56-60); 

determining whether said user is authorized to access said network from said 
physical location of said login or attempted login (column 5, lines 3-21). 

Claim 2 is rejected as applied above in rejecting claim 1. Furthermore, Ensor discloses: 
The method of claim 1 , further comprising determining whether preventive action 
is necessary and, if so, automatically initiating preventive action (column 5, lines 41-53). 

Claim 3 is rejected as applied above in rejecting claim 2. Furthermore, Ensor discloses: 

The method of claim 2, wherein said preventive action comprises generating an 
alert (column 5, lines 41-53). 

Claim 4 is rejected as applied above in rejecting claim 2. Furthermore, Ensor discloses: 

The method of claim 2, wherein said preventive action comprises disconnecting 
said workstation from said network (column 5, lines 50-53). 
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Claim 5 is rejected as applied above in rejecting claim 2. Furthermore, Ensor discloses: 

The method of claim 2, wherein said preventive action comprises generating a 
notification message that said user is accessing said computer network from an 
unauthorized location (column 5, lines 41-53). 

Claim 6 is rejected as applied above in rejecting claim 1 . Furthermore, Ensor discloses: 

The method of claim 1, further comprising storing information regarding said 
physical location of said login or attempted login (column 5, lines 54-60). 

Claim 7 is rejected as applied above in rejecting claim 1. Furthermore, Ensor discloses: 

The method of claim 1, further comprising storing information regarding said 
workstation associated with said login or attempted login (column 5, lines 54-60). 

Claim 8 is rejected as applied above in rejecting claim 7. Furthermore, Ensor discloses: 

The method of claim 7, wherein said workstation information includes one or 
more of the following types of information: 

an IP/MAC address of said workstation, a date and time of each login attempt, a 
date and time of each successful login, login type description, network security agent, 
domain address, information regarding which network resources were accessed, server 
identification, the number of login attempts, host name data, jack or outlet information, 
port identification, or any other circuit trace information (column 4, lines 51-60). 
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Claim 11 is rejected as applied above in rejecting claim 1. Furthermore, Ensor 
discloses: 

The method of claim 1 , further comprising associating said user with a 
workstation (column 3, lines 1-17, 62-67). 

Regarding claim 12, Ensor discloses: 

A method for providing security to a computer network by monitoring a network 
login or login attempt from a particular workstation, said method comprising: 

associating a workstation to a physical location (column 3, lines 1-17: identifiable 
coupling); 

associating a network user to said workstation (column 3, lines 1-17, 62-67); 

monitoring a computer network to determine a network login or attempted login of 
said user (column 4, lines 51-59); 

determining which workstation said login or attempted login is generated from 
(column 4, lines 56-60); 

determining whether said user is authorized to access said network from said 
workstation of said login or attempted login (column 5, lines 3-21). 

Regarding claim 13, Ensor discloses: 

A network security system for a plurality workstations coupled via a local area 
network, said network said security system comprising: 
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electronic storage for associating said workstations to a user and a physical 
location (column 3, lines 1-17, 62-67); and 

one or more processors for receiving login information from said workstations 
and accessing said electronic storage to determine whether said user or said 
workstation is authorized to login to said network from said physical location (column 5, 
lines 3-21). 

Claim 14 is rejected as applied above in rejecting claim 13. Furthermore, Ensor 
discloses: 

The system of claim 13, wherein said one or more processors generates an alert 
based said determination (column 5, lines 41-53). 

Claim 17 is rejected as applied above in rejecting claim 14. Furthermore, Ensor 
discloses: 

The system of claim 14, wherein said alert comprises a termination signal 
(column 5, lines 50-53). 

Regarding claim 21, Ensor discloses: 

Computer readable medium having computer readable code for causing one or 
more processors to: 

associating a workstation to a physical location (column 3, lines 1-17: identifiable 
coupling); 
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associating a networl< user to said worl^station (column 3, lines 1-17, 62-67); 

monitoring a computer network to determine a network login or attempted login of 
said user (column 4, lines 51-59); 

determining a physical location of said login or attempted login (column 4, lines 
56-60); 

determining whether said user is authorized to access said network from said 
physical location of said login or attempted login (column 5, lines 3-21). 

Regarding claim 22, Ensor discloses: 

A network security system for a plurality workstations coupled via a local area 
network each workstation being associated with a specific user and coupled to one of a 
plurality of data ports of a patch panel, said patch panel being coupled to a computer 
network, said security system comprising: 

a workstation associated with a physical location and a user (column 3, lines 1- 
17: identifiable coupling); 

a monitoring device for determining a network login or attempted login of said 
user, a device for determining a physical location of said login or attempted login 
(column 4, lines 56-60); 

wherein said system determines whether said user is authorized to access said 
network from said physical location of said login or attempted login (column 5, lines 3- 
21). 
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Claim Rejections - 35 USC § 103 

The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set 
forth in section 102 of this title, if the differences between the subject matter sought to be patented and 
the phor art are such that the subject matter as a whole would have been obvious at the time the 
invention was made to a person having ordinary sl^ill in the art to which said subject matter pertains. 
Patentability shall not be negatived by the manner in which the invention was made. 

Claims 9-10, and 18-20 are rejected under 35 U.S.C. 103(a) as being 

unpatentable over Ensor et al. (U.S. Patent 5,721 ,780) in view of Kondo et al. (U.S. 

Patent 5,684,957). 

Claims 9-10 are rejected as applied above in rejecting claim 1 . Ensor does not 
explicitly disclose generating an event log. Kondo discloses generating an event log 
that comprises information about the physical location of the login attempt (Kondo: 
column 17, lines 36-53). It would have been obvious to use the event log of Kondo to 
log the physical information of the user making the login attempts to "provide an early 
detection of an unauthorized entry from inside" (Kondo: column 4, lines 60-67). 

Claims 18-20 are rejected as applied above in rejecting claim 14. Ensor does not 
explicitly disclose generating an event log. Kondo discloses generating an event log 
that comprises information about the physical location of the login attempt (Kondo: 
column 17, lines 36-53). It would have been obvious to use the event log of Kondo to 
log the physical information of the user making the login attempts to "provide an early 
detection of an unauthorized entry from inside" (Kondo: column 4, lines 60-67). 
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Claims 15-16 are rejected under 35 U.S.C. 103(a) as being unpatentable over 
Ensor at al. (U.S. Patent 5,721 ,780) in view of Day (U.S. Patent 6,31 1 ,274). 

Claims 15-16 are rejected as applied above in rejecting claim 14. Ensor does not 
explicitly disclose that the alert comprises an email notification or by sending a pager 
notification. Day discloses that an alert action can comprise sending an email message 
and/or sending a message to a pager (Day: column 5, lines 33-37). It would have been 
obvious to use these methods of issuing an alert in the system of Ensor to "provide 
assurance that the purported source of an alert message is a true source" (Day: 
column 1, lines 51-55). 

Conclusion 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to KAVEH ABRISHAMKAR whose telephone number is 
(571)272-3786. The examiner can normally be reached on Monday thru Friday 8-5. 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Ayaz Sheikh can be reached on 571-272-3795. The fax phone number for 
the organization where this application or proceeding is assigned is 571-273-8300. 
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Information regarding the status of an application may be obtained from the 
Patent Application Information Retrieval (PAIR) system. Status information for 
published applications may be obtained from either Private PAIR or Public PAIR. 
Status information for unpublished applications is available through Private PAIR only. 
For more information about the PAIR system, see http://pair-direct.uspto.gov. Should 
you have questions on access to the Private PAIR system, contact the Electronic 
Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a 
USPTO Customer Service Representative or access to the automated information 
system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 

/Kaveh Abrishamkar/ 
Examiner, Art Unit 2131 

IK. A./ 
08/21/2008 

Examiner, Art Unit 2131 



